You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/includes/3-address-compliance-requirements-microsoft-purview.md
+8-6Lines changed: 8 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ Microsoft Purview combines multiple solution areas to address compliance require
7
7
8
8
| Solution Area | Purpose | Key Solutions |
9
9
|--------------|---------|---------------|
10
-
|**Data security**| Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management, Information Barriers, Privileged Access Management |
10
+
|**Data security**| Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management, Information Barriers, Privileged Access Management, Data Security Investigations|
11
11
|**Data governance**| Manage and catalog data across your estate | Data Map, Unified Catalog |
12
12
|**Data compliance**| Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, Communication Compliance, eDiscovery, Data Lifecycle Management, Records Management |
13
13
@@ -44,7 +44,7 @@ Regulations often require controls to prevent unauthorized disclosure of sensiti
44
44
Design your DLP policies to address specific regulatory requirements:
45
45
46
46
-**Policy conditions** - Define what sensitive data to protect based on sensitive information types, labels, or content patterns
47
-
-**Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, endpoints, Defender for Cloud Apps)
47
+
-**Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, devices, non-Microsoft cloud apps, on-premises repositories, Fabric and Power BI, and Microsoft 365 Copilot)
48
48
-**Policy actions** - Configure responses from audit-only monitoring to blocking with user override to complete restriction
49
49
50
50
DLP integrates with your sensitivity labels, so protection can follow content based on its classification. This integration is particularly valuable for requirements that mandate different handling based on data sensitivity levels.
@@ -54,18 +54,20 @@ DLP integrates with your sensitivity labels, so protection can follow content ba
54
54
Compliance frameworks require organizations to maintain audit trails and respond to legal or regulatory inquiries. Purview provides several solutions for these requirements:
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Design your audit strategy to:
57
+
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Audit is available in two tiers—Audit (Standard) provides 180-day retention with basic search and export, while Audit (Premium) adds custom retention policies (up to 10 years with an add-on license), intelligent insights for forensic investigations, and higher API bandwidth. Design your audit strategy to:
58
58
59
-
-Enable appropriate audit logging levels based on regulatory requirements
60
-
- Configure retention periods that meet legal hold obligations
59
+
-Select the appropriate audit tier based on regulatory retention and investigation requirements
60
+
- Configure retention policies that meet legal hold obligations
61
61
- Establish processes for searching and exporting audit data for investigations
**Microsoft Purview eDiscovery** helps you identify, preserve, collect, and export content for legal matters. For compliance purposes, design workflows that:
64
65
65
66
- Create legal holds to preserve relevant content
66
67
- Define search criteria that capture required data without over-collection
67
68
- Export content in formats suitable for regulatory review
**Microsoft Purview Records Management** applies retention and deletion policies to meet recordkeeping requirements. Consider how file plans, retention labels, and disposition reviews align with your regulatory obligations.
70
72
71
73
## Managing insider risk
@@ -87,7 +89,7 @@ As discussed in the AI compliance considerations unit, organizations deploying A
87
89
**Data Security Posture Management (DSPM) (preview)** provides visibility and control for both traditional applications and AI apps and agents. Use DSPM to:
88
90
89
91
- Discover sensitive data that may be exposed to AI applications
90
-
- Monitor how AI apps access and process organizational data through AI observability dashboards
92
+
- Monitor how AI apps access and process organizational data through data security insights and trend analysis
91
93
- Identify and remediate data security risks before they become compliance issues
0 commit comments